Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-435 2005-08-16 ---------------------------------------------------------------------Product : Fedora Core 3 Name : ncpfs Version : 2.2.4 Release : 4.FC3.1 Summary : Utilities for the ncpfs filesystem, a NetWare client for Linux. Description : Ncpfs is a filesystem which understands the Novell NetWare(TM) NCP protocol. Functionally, NCP is used for NetWare the way NFS is used in the TCP/IP world. For a Linux system to mount a NetWare filesystem, it needs a special mount program. The ncpfs package contains such a mount program plus other tools for configuring and using the ncpfs filesystem. Install the ncpfs package if you need to use the ncpfs filesystem to use Novell NetWare files or services. ---------------------------------------------------------------------* Fri Jun 17 2005 Jiri Ryska 2.2.4-4.FC3.1 - fixed getuid security bug CAN-2005-0014 - fixed security bug CAN-2004-1079 * Mon Apr 11 2005 Jiri Ryska 2.2.4-4.FC3 - fixed getuid security bug CAN-2005-0013 ---------------------------------------------------------------------This update can be downloaded from: 6af0d3c19911051510d951cefd6666ed SRPMS/ncpfs-2.2.4-4.FC3.1.src.rpm fdc4956a24599f539dc8c70e5060631b x86_64/ncpfs-2.2.4-4.FC3.1.x86_64.rpm 61bbe162ded6e049d87bf08375d7c43d x86_64/ipxutils-2.2.4-4.FC3.1.x86_64.rpm 760a4728c89cbbd94aeb355d74292157 x86_64/debug/ncpfs-debuginfo-2.2.4-4.FC3.1.x86_64.rpm 09dc713963e1af3e68756237fc7fc621 i386/ncpfs-2.2.4-4.FC3.1.i386.rpm 439ec771747839c02362a2c198072d04 i386/ipxutils-2.2.4-4.FC3.1.i386.rpm 20cda6efc8a8b970fdce80140d245a5f i386/debug/ncpfs-debuginfo-2.2.4-4.FC3.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailinglist
The ncpfs utilities contain multiple flaws, potentially resulting in the remote execution of arbitrary code or local file access with elevated privileges. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ncpfs: Multiple vulnerabilities Date: January 30, 2005 Bugs: #77414 ID: 200501-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The ncpfs utilities contain multiple flaws, potentially resulting in the remote execution of arbitrary code or local file access with elevated privileges. Background ========= ncpfs is a NCP protocol network filesystem driver that allows access to NetWare services, to mount volumes of NetWare servers or print to NetWare print queues. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-fs/ncpfs < 2.2.6 > = 2.2.6 Description ========== Erik Sjolund discovered two vulnerabilities in the programs bundled with ncpfs: there is a potentially exploitable buffer overflow in ncplogin (CAN-2005-0014), and due to a flaw in nwclient.c, utilities using the NetWare client functions insecurely access files with elevated privileges (CAN-2005-0013). Impact ===== The buffer overflow might allow a malicious remote NetWare server to execute arbitrary code on the NetWare client. Furthermore, a local attacker may be able to create links and access files with elevated privileges using SUID ncpfs utilities. Workaround ========= There is no knownworkaround at this time. Resolution ========= All ncpfs users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-fs/ncpfs-2.2.6" References ========= [ 1 ] CAN-2005-0013 https://www.cve.org/CVERecord?id=CVE-CAN-2005-0013 [ 2 ] CAN-2005-0014 https://www.cve.org/CVERecord?id=CVE-CAN-2005-0014 [ 3 ] ncpfs ChangeLog Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-44 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.